Zscaler & Zero Trust operations glossary ยท Products & platform

What is the Zscaler Client Connector (ZCC)?

Definition

The Zscaler Client Connector (ZCC) is the endpoint agent of the Zscaler platform. It captures traffic from endpoint devices and forwards it to the Zero Trust Exchange. A single client connects three services: internet traffic is inspected through Zscaler Internet Access (ZIA), access to internal applications runs through Zscaler Private Access (ZPA), and Zscaler Digital Experience (ZDX) receives telemetry on device, network and applications. ZCC authenticates the user against the connected identity provider and applies centrally managed profiles that determine forwarding behaviour per environment. For IT operations, the client is therefore the point where security, connectivity and troubleshooting come together.

Zscaler Client Connector in detail

After sign-in, the client builds tunnels to the Zscaler cloud depending on its configuration and forwards the captured traffic there. Two centrally managed building blocks control how this happens: the forwarding profile determines how internet traffic is routed, for example in tunnel mode or through a PAC file, while the app profile governs platform-specific settings and exceptions. The client can also recognise defined trusted networks and adjust its behaviour there.

ZCC is managed through its own admin portal, where profiles, policies and client versions are maintained centrally. The client runs on common desktop and mobile platforms, including Windows, macOS, Linux, iOS and Android. Whether users may disable the client themselves can be restricted by policy: Zscaler provides separate passwords for this, for example for uninstalling the client and, separately, for turning off individual services such as ZDX or endpoint DLP. Removing a device only signs the client out; it does not uninstall it.

Why ZCC matters in Zscaler operations

A large share of Zscaler tickets lands with the client first: 'no internet', 'application unreachable', 'everything is slow'. The first useful question is almost always: is ZCC signed in, which profile is active, is the tunnel up? Classic causes such as a captive portal on hotel Wi-Fi explain many cases. Anyone who cannot see this status is left guessing or has to escalate to administrators.

The client is also business-critical across the whole fleet: outdated versions cause known bugs, and as the enforcement point for security policy it must not be disabled unnoticed. A disabled client means either uninspected traffic or missing access, depending on the architecture. For evidence purposes, what counts is being able to prove the actual state of clients, not just the policies on paper.

Common sources of error

ZCC in practice: what CentaurNexus contributes

CentaurNexus puts the client context to work for support: User Support Center shows a 360-degree user finding across ZIA, ZPA and ZDX in one view, without the helpdesk needing Zscaler admin rights. Connectivity Triage Map combines the ZDX chain with policy status and names the cause in plain language: ISP, Wi-Fi, device or Zscaler. The guide below shows how this looks in daily practice: Is it Zscaler or the Wi-Fi?. If a compromised device needs to be removed, Emergency User Isolation isolates it from ZIA and ZPA. All write actions are auditable, optionally with four-eyes approval.

See in the live demo how the helpdesk views ZCC context for each user, with no Zscaler admin rights at all.Watch the live demo

Related terms

Frequently asked questions about the Zscaler Client Connector

What exactly does the Zscaler Client Connector do?

The client signs the user in to the Zscaler platform, captures the device's traffic and forwards it according to the centrally managed profiles: internet traffic goes to ZIA for inspection, access to internal applications goes to ZPA. It also supplies telemetry for ZDX, which is used to measure the digital user experience.

Which operating systems does the Zscaler Client Connector run on?

Zscaler provides the Client Connector for common desktop and mobile platforms, including Windows, macOS, Linux, iOS and Android. The feature set and configuration options differ by platform. The authoritative source is the official compatibility list in the Zscaler Help Portal, which documents supported versions and platform-specific details.

Can a user simply disable the Zscaler Client Connector?

That depends on the configuration. Administrators can restrict disabling or signing out by policy, for example with an additional password. In well-run environments this is the norm, because a disabled client means either uninspected traffic or missing access to internal applications, depending on the setup.

How does ZCC differ from a classic VPN client?

A VPN client builds a tunnel into a network where the user gets broad access. ZCC instead connects to the Zscaler cloud: internet traffic is inspected inline there, and internal applications become reachable individually and on a policy basis through ZPA. The network itself stays hidden, which significantly reduces the attack surface.

How does the helpdesk recognise whether ZCC is the cause of a problem?

It helps to look at the chain: is the client signed in, which profile is active, is the tunnel up, and what do the ZDX values show for device and network? If the telemetry shows a healthy device and a stable network, the cause is more likely with the application or the provider than with the client.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.